Maintenance for the week of April 6:
• ESO Store and Account System for maintenance – April 8, 9:00AM EDT (13:00 UTC) - 6:00PM EDT (22:00 UTC)
We are currently investigating connection issues some players are having on the European megaservers. We will update as new information becomes available.
Addon API Security Flaw: Bank is Accessible from Housing Storage Chests Using Addon API
RequestMoveItem Lua API call is successful between bank and inventory even though I am accessing a storage chest.
I assume this is unintended behavior as it is impossible to perform such an action in the vanilla UI.
Here is the addon that replicates such a bug:
https://esoui.com/downloads/info430-CDGBankStacker.html
Even though this addon makes it easy to replicate this bug, I assume other addons could potentially exploit such a bug for even more broken interactions.
Steps to replicate:
- Install add-on from link above.
- Split a stack of a stackable item and deposit one stack into the bank.
- Go to housing and access storage chest.
- Observe successful stacking to bank from chat log and item count.
Here's a link to a video proving such an action is possible:
https://youtu.be/X3TrDGdtjDE
EDIT:
Here's the ticket number for my in-game bug report submission: 200525-011665
Edited by Infinity_Knives on May 26, 2020 2:02AM